Malware

How to remove “Cerbu.126906 (B)”?

Malware Removal

The Cerbu.126906 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Cerbu.126906 (B) virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Likely virus infection of existing system binary

How to determine Cerbu.126906 (B)?


File Info:

name: 0FAB06859086DA8415BB.mlw
path: /opt/CAPEv2/storage/binaries/a3705c18c37ecd4cbb666d365ee2e6a12925f495db2bf70b7257dac8d9b5bcb3
crc32: 3F688F0D
md5: 0fab06859086da8415bb3c258ba14722
sha1: fdef95799911ae7c65b5e39358fac96f1669e66a
sha256: a3705c18c37ecd4cbb666d365ee2e6a12925f495db2bf70b7257dac8d9b5bcb3
sha512: c52cdb3233a665684ae76aed6ce452f926cc13186c7ef8d072a961b988b4e8ac82fdc4ef1294f4a184ac9099d037606b68cd138761725c836c1d90f5d49b874f
ssdeep: 98304:VB7Q9Js3z4TUxXBwPF7r2OttCF+Q8GHTuJw+vigXk5sTQ2zqx0tuwGRzG/uUcpxz:LU7ssTAX6dzC6Jw+KgXb82zqx0cBR+eh
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19346339A064877F0F4ADD5F91E70C1524D166F40C7283A38696EF04A793B518CBECF6A
sha3_384: df31bd571d545ce801d690adaa767c3de6e91e938508f070bb46784094ad470aa3a5175609b041dff67860eba88b3f3d
ep_bytes: 558bec83c4cc53565733c08945f08945
timestamp: 1992-06-19 22:22:17

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName: Data Doctor Pvt. Ltd.
FileDescription: DR (Professional) Recovery - Demo Setup
FileVersion:
LegalCopyright:
Translation: 0x0409 0x04e4

Cerbu.126906 (B) also known as:

LionicTrojan.Win32.Ekstak.4!c
MicroWorld-eScanGen:Variant.Cerbu.126906
FireEyeGen:Variant.Cerbu.126906
McAfeeArtemis!0FAB06859086
CylanceUnsafe
SangforTrojan.Win32.Ekstak.akwyb
K7AntiVirusTrojan ( 005722f11 )
AlibabaTrojanDropper:Win32/Ekstak.744795a8
K7GWTrojan ( 005722f11 )
SymantecTrojan.Gen.2
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
TrendMicro-HouseCallTROJ_GEN.R002C0WLV21
Paloaltogeneric.ml
KasperskyTrojan.Win32.Ekstak.akwyb
BitDefenderGen:Variant.Cerbu.126906
AvastWin32:Trojan-gen
TencentWin32.Trojan.Ekstak.Jmp
Ad-AwareGen:Variant.Cerbu.126906
EmsisoftGen:Variant.Cerbu.126906 (B)
TrendMicroTROJ_GEN.R002C0WLV21
McAfee-GW-EditionBehavesLike.Win32.BadFile.tc
SophosMal/Generic-S
GDataWin32.Backdoor.Bodelph.Z6V4VP
JiangminTrojan.Ekstak.buyt
GridinsoftRansom.Win32.Wacatac.sa
ViRobotTrojan.Win32.Z.Agent.5427756
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Trojan-gen.R461233
VBA32Trojan.Ekstak
ALYacGen:Variant.Cerbu.126906
MAXmalware (ai score=81)
MalwarebytesAdware.DownloadAssistant
FortinetW32/Agent.SLC!tr
AVGWin32:Trojan-gen
PandaTrj/CI.A

How to remove Cerbu.126906 (B)?

Cerbu.126906 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment